Yolo · Android · iOS
Yolo — Privacy Policy
Effective date: 4 July 2026 · Last updated: 10 October 2026
English · Deutsch
The short version: Yolo processes sensitive health data to do its job. That data is stored in Switzerland (Google Cloud region Zurich), is never sold, is never used for advertising, and is only sent to an AI model when you explicitly ask for an AI-powered feature and have consented to it. You can export or permanently delete everything, at any time, from inside the app.
1. Who we are
The controller responsible for your personal data is:
dataWorks GmbH
Seestrasse 59, 8702 Zollikon, Switzerland
UID CHE-196.074.218
Email: yolo@data-works.ch
This policy is written to satisfy both the EU General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (nDSG).
2. What data we process
- Account data — Phone number, user ID, sign-in timestamps. Source: You, at sign-up
- Profile data — Age, sex, height, weight, activity level, diet mode, allergies. Source: You, during onboarding
- Nutrition data — Meal logs, food portions, water intake, custom foods and recipes. Source: You, while using the app
- Meal photos & voice recordings — Photos of your food; voice descriptions of meals. Source: You, when you choose photo or voice logging
- Health data (special category) — Weight, steps, active energy, heart rate, HRV, resting heart rate, sleep, exercise sessions from Apple Health / Health Connect; mood check-ins; lifestyle questionnaire answers. Source: Your device's health platform, only after you grant permission; you
- Purchase data — Subscription status, product ID, trial state (no card numbers — payment runs through Apple/Google). Source: App Store / Google Play via RevenueCat
- Usage data — Screens viewed, features used, app opened events. Source: Automatically; in the EU/EEA and the UK only with your consent, elsewhere unless you switch it off in Settings
- Ad measurement data — Your device's advertising ID (on iOS only if you allow tracking), which ad led to your install, and whether you started a trial or subscription. Source: Automatically; in the EU/EEA and the UK only with your consent, elsewhere unless you switch off "Ad measurement" in Settings
3. Why we process it, and on what legal basis
- Providing the core service: logging meals, calculating your nutrition score and targets, syncing across devices — Contract performance (Art. 6(1)(b) GDPR)
- Processing health data (Apple Health / Health Connect metrics, mood) to personalise targets, correlate nutrition with health metrics, and generate reports — Your explicit consent (Art. 9(2)(a) GDPR), given via the OS permission dialogs and in-app consent prompts. You can withdraw it at any time by revoking health permissions or deleting your data.
- AI-powered features: food recognition from photos, meal analysis from text or voice, health reports, experiment summaries — Your explicit consent (Art. 9(2)(a) GDPR), requested in-app before the first AI analysis
- Processing purchases and unlocking premium features — Contract performance (Art. 6(1)(b) GDPR)
- Analytics to understand which features are used and improve the app — In the EU/EEA and the UK: your consent (Art. 6(1)(a) GDPR); off until you opt in, withdrawable in Settings. In Switzerland: processing of usage data under the nDSG, with the information and right to refuse required by Art. 45c lit. b of the Telecommunications Act (FMG); on by default, can be switched off in Settings at any time. Elsewhere: on by default, can be switched off in Settings at any time
- Ad measurement: finding out which of our ads lead to installs, trials and subscriptions (Google Ads). Not used to personalise ads or build advertising audiences — In the EU/EEA and the UK: your consent (Art. 6(1)(a) GDPR), asked together with analytics; withdrawable in Settings. In Switzerland and elsewhere: on by default, can be switched off in Settings at any time. On iOS, the advertising ID (IDFA) is only read if you allow tracking in the system prompt
- Security, abuse prevention and enforcing fair use of AI features — Legitimate interest (Art. 6(1)(f) GDPR) in keeping the service secure and available
4. AI processing — what exactly happens
Some features send data to a large language model (Google Gemini) running in Google Cloud's europe-west6 (Zurich) region, called from our own backend:
- Photo logging: your meal photo is analysed to identify foods and portions.
- Voice / text logging: your description is analysed to extract foods and amounts.
- Health report & analysis: aggregated nutrition and health metrics are analysed to produce your personal report.
These requests are used solely to produce your result. They are not used to train AI models, and results are stored only in your own account. AI features run only after you have given explicit consent in the app, and each one is triggered by your own action — nothing is analysed in the background.
AI output can be wrong. Results are personal insights, not medical advice — see the Terms of Service for the full health disclaimer.
5. Who we share data with
We never sell your data, and your health and nutrition data is never used for advertising. We use these processors:
- Google Cloud / Firebase (Google Ireland Ltd.) — Database, file storage, authentication, cloud functions, crash reporting, analytics (consent-based in the EU/EEA and the UK, opt-out elsewhere). Location / safeguards: Primary storage and processing in Zurich, Switzerland (europe-west6). Some Firebase services may process data in the EU/US under the EU-U.S. Data Privacy Framework and Standard Contractual Clauses.
- Google Ads (Google Ireland Ltd.) — Ad measurement described in section 3. Location / safeguards: Receives the advertising ID and the install, trial and subscription events via Firebase, never health or nutrition data. EU-U.S. Data Privacy Framework / SCCs.
- Google Gemini API — AI analysis described in section 4. Location / safeguards: europe-west6 (Zurich); not used for model training
- RevenueCat, Inc. — Subscription management. Location / safeguards: USA — EU-U.S. Data Privacy Framework / SCCs. Receives a pseudonymous user ID and purchase data, never health data.
- Apple App Store / Google Play — Payment processing. Location / safeguards: Per their own terms; we never see your payment details
- Open Food Facts — Barcode lookups for packaged products. Location / safeguards: France (EU). Receives only the barcode you scan, never your identity.
We may also disclose data if required by law, or in connection with a merger or acquisition (in which case this policy continues to apply to data collected under it).
6. Apple Health & Health Connect
Yolo reads health metrics only after you grant permission in iOS Health or Android Health Connect, and you choose exactly which data types to share. Data obtained from these platforms is used only to provide the features described above. It is never used for advertising or marketing, never sold, and never shared with third parties for their own purposes — as required by Apple's and Google's health data policies. You can revoke access at any time in your device settings; Yolo then stops reading new data.
7. International transfers
Your data is primarily stored and processed in Switzerland (Google Cloud, Zurich). Where a processor operates from the USA (e.g. RevenueCat, some Firebase services), transfers are protected by the EU-U.S. / Swiss-U.S. Data Privacy Framework or Standard Contractual Clauses. You can request a copy of the applicable safeguards via the contact address above.
8. How long we keep data
- Account, profile, nutrition and health data — Until you delete your account or the specific entry
- Meal photos and voice recordings — Voice recordings and AI-chat media are deleted after analysis. Meal photos remain in your account until you delete the entry or your account.
- Analytics events — Up to 14 months (Google Analytics for Firebase default)
- Backups — Deleted data leaves backup systems within 30 days
When you delete your account (in the app under Settings → Delete Account, or via this page), your Firebase Auth account, database records and stored files are permanently deleted.
9. Your rights
Under the GDPR and the nDSG you can, at any time:
- Access your data (Art. 15 GDPR / Art. 25 nDSG) — the app's CSV export gives you this instantly;
- Rectify inaccurate data (Art. 16) — editable directly in the app;
- Erase your data (Art. 17) — in-app account deletion, or see delete your account;
- Export your data in a machine-readable format (Art. 20 / Art. 28 nDSG) — Settings → Export Tracking Data;
- Restrict or object to processing (Art. 18, 21);
- Withdraw consent (Art. 7(3)) — revoke health permissions in your OS settings, turn off usage statistics or ad measurement in the app's settings, or deny tracking under iOS Settings → Privacy → Tracking, without affecting the lawfulness of prior processing.
To exercise a right that isn't self-service, email yolo@data-works.ch. We respond within 30 days.
You can also lodge a complaint with a supervisory authority: in Switzerland the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, CH-3003 Bern, or your local EU data protection authority.
10. Security
All data is encrypted in transit (TLS) and at rest. Access is restricted per user through Firebase security rules — your data is readable only by your own authenticated account. Backend AI functions require authentication and app attestation. Meal photos are stripped of EXIF metadata (including location) before upload.
11. Children
Yolo is not directed at children and requires you to be at least 16 years old. We do not knowingly process data of anyone younger; if you believe a child is using the app, contact us and we will delete the account.
12. Automated decision-making
Yolo computes scores, targets and reports automatically, but these are informational features you request — they produce no legal or similarly significant effects on you, and no decisions are made about you without your involvement (Art. 22 GDPR).
13. Changes to this policy
If we change this policy materially, we will inform you in the app before the change takes effect and, where required, ask for your consent again. The "last updated" date at the top always reflects the current version.
14. Contact
dataWorks GmbH · Seestrasse 59, 8702 Zollikon, Switzerland · UID CHE-196.074.218 · yolo@data-works.ch